The Lab: findings, interface mockups and open proposals, published as they happen
A new top-level section for work in progress. The rest of the site says only what it can defend; the Lab is looser about status and no looser at all about sourcing, which is what the four state labels are for.
- The Lab↗ — the index, generated from the entries, plus how to read each state. A finding is something quoted from a primary source. A mockup is a drawing to be argued with. A proposal is a change we are asking somebody else to make. An open question is one we cannot answer and would rather not have rediscovered.
- Lab 01 — the grant is user-shaped, not data-shaped↗. What a connector actually grants when somebody plugs an assistant into their mail or their files. Four quotes, verbatim, from the vendors' own documentation, each verified against its source page on 12 September 2026: the narrowest Gmail scope that returns a message body is described as view your email messages and settings; Drive's default corpus is defined by Google as files owned by or shared to the user; Anthropic's own Microsoft 365 connector guide states that site-specific permissioning is not supported because the underlying search is tenant-wide; and the official Dropbox MCP server requests eight scopes including two writes and two sharing scopes. Plus the four places a vendor's advertised capability and their granted scope disagree — published unresolved, because settling them would mean probing somebody else's service, which is out of bounds.
- Lab 02 — what buying a behaviour policy would look like↗. Twelve stages from a stranger's first question to a recomputing vault with a read key they can hand an underwriter, with five drawn as interface mockups: the front-page encounter, the five-shape picker, the draft, the correction, and the delivery. None of it is built. The draft mockup is the load-bearing one and it carries no score, four counts, a barrier per capability and whose material each one touches.
- Lab 03 — changes we are asking of the behaviour-policy site↗.
Three open requests against
abp.sgit.ai, which we render against and do not maintain: amaterialproperty for the capability grammar, four connector deployment shapes, and the provenance conventions we would need to render any of it. Published rather than emailed, with an argument for moving it to a shared vault if there is a second round.
Nav. Lab is top-level, between the demos and Lisbon. Its entries are unlisted, because the index is generated from them and a dropdown of experiments would grow without bound.
One defect caught by review, and a test so it cannot recur. The delivery mockup needed a read key and got filled in with a real one — the Licence to Operate vault's published key, paired with an invented vault id. It is a public key and nothing was exposed, but sample data has to be obviously sample data. It is now a visible placeholder, and a test asserts that no page in the Lab contains anything shaped like a read key. Tests: 20.